Vetting Browser Extensions for Security Vulnerabilities with VEX.

The browser has become the de facto platform for everyday computation and a popular target for attackers of computer systems. Among the many potential attacks that target or exploit browsers, vulnerabilities in browser extensions have received relatively little attention. Currently, extensions are v...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 54; no. 9; pp. 91 - 100
Autores principales: Bandhakavi, Sruthi, Tiku, Nandit, Pittman, Wyatt, King, Samuel T., Madhusudan, P., Winslett, Marianne
Formato: Artículo
Publicado: Association for Computing Machinery Sep2011
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=67134753&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 67134753
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Sep2011
      vid: 54
      iid: 9
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        67134753
        10.1145/1995376.1995398
      ppf: 91
      ppct: 9
      formats:
      tig:
        atl: Vetting Browser Extensions for Security Vulnerabilities with VEX.
      aug:
        au:
          Bandhakavi, Sruthi
          Tiku, Nandit
          Pittman, Wyatt
          King, Samuel T.
          Madhusudan, P.
          Winslett, Marianne
        affil: Department of Computer Science, University of Illinois at Urbana, Champaign
      su:
        Web browser security
        Anti-malware (Computer software)
        Malware
        Computer security
        JavaScript programming language
        World Wide Web
      sug:
        subj:
          Web browser security
          Anti-malware (Computer software)
          Malware
          Computer security
          JavaScript programming language
          World Wide Web
      ab: The browser has become the de facto platform for everyday computation and a popular target for attackers of computer systems. Among the many potential attacks that target or exploit browsers, vulnerabilities in browser extensions have received relatively little attention. Currently, extensions are vetted by manual inspection, which is time consuming and subject to human error. In this paper, we present Vex, a framework for applying static information flow analysis to JavaScript code to identify security vulnerabilities in browser extensions. We describe several patterns of flows that can lead to privilege escalations in Firefox extensions. Vex analyzes Firefox extensions for such flow patterns using high-precision, context-sensitive, flow-sensitive static analysis. We subject 2460 browser extensions to the analysis, and Vex finds 5 of the 18 previously known vulnerabilities and 7 previously unknown vulnerabilities.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2011
    holdings:
      @attributes:
        islocal: N